Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 114 additions & 0 deletions patches/backported-patches.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -88,5 +88,119 @@
"patch_path": "N/A",
"link": "https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158",
"note": "Notebook Restricted-Mode bypass via mermaid render. Upstream vulnerable file extensions/mermaid-markdown-features/preview-src/notebook/index.ts (the 'temp.innerHTML = result' sink and renderMermaidBlocksInElement) does not exist in this branch's shipped source. The only mermaid extension here, mermaid-chat-features, renders diagrams via escapeHtmlText() into a <pre> and uses textContent (chat-webview-src/mermaidWebview.ts) inside a sandboxed webview with strict nonce CSP - no innerHTML of untrusted content. The markdown-language-features notebook renderer already sanitizes untrusted HTML with DOMPurify. No equivalent vulnerable innerHTML/insertAdjacentHTML sink for untrusted render output exists."
},
{
"finding_id": "CVE-2026-70336",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-fp6w-v29h-43rj",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69320",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-h29r-p8vr-4vfm",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69278",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "GHSA-h9j4-x76r-fvj4",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "CVE-2026-58650",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "GHSA-h6v9-3cqc-v234",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "CVE-2026-47285",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "GHSA-vcpf-2mpp-vx3v",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "CVE-2026-65675",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-3hjg-cwxj-qfc6",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-70335",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-w79w-rj9h-vg4f",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-59113",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "GHSA-36qf-jgq9-4m6j",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "CVE-2026-69306",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
},
{
"finding_id": "GHSA-6xp2-9cj3-f488",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
}
]
109 changes: 109 additions & 0 deletions patches/common/fix-block-privileged-url-payload.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
Block privileged URL payload options in server

Prevents environment variable injection via startParamsEnv by ensuring
VSCODE_* critical vars cannot be overridden, sanitizes resolverEnv before
use in terminal channel, removes dangerous env vars case-insensitively
across all platforms, and restricts extension dev payload options to
non-production builds only.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f
@finding-id: CVE-2026-70336 GHSA-fp6w-v29h-43rj CVE-2026-69320 GHSA-h29r-p8vr-4vfm
Index: b/src/vs/base/common/processes.ts
===================================================================
--- a/src/vs/base/common/processes.ts
+++ b/src/vs/base/common/processes.ts
@@ -3,7 +3,7 @@
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/

-import { IProcessEnvironment, isLinux } from './platform.js';
+import { IProcessEnvironment } from './platform.js';

/**
* Options to be passed to the external program or shell.
@@ -136,13 +136,16 @@ export function removeDangerousEnvVariab
return;
}

- // Unset `DEBUG`, as an invalid value might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/130072
- delete env['DEBUG'];
-
- if (isLinux) {
- // Unset `LD_PRELOAD`, as it might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/134177
- delete env['LD_PRELOAD'];
+ const dangerousEnvVariables = new Set([
+ 'DEBUG',
+ 'NODE_OPTIONS',
+ 'VSCODE_NODE_OPTIONS',
+ 'LD_PRELOAD',
+ 'DYLD_INSERT_LIBRARIES'
+ ]);
+ for (const key of Object.keys(env)) {
+ if (dangerousEnvVariables.has(key.toUpperCase())) {
+ delete env[key];
+ }
}
}
Index: b/src/vs/server/node/extensionHostConnection.ts
===================================================================
--- a/src/vs/server/node/extensionHostConnection.ts
+++ b/src/vs/server/node/extensionHostConnection.ts
@@ -40,12 +40,10 @@ export async function buildUserEnvironme
const env: IProcessEnvironment = {
...processEnv,
...userShellEnv,
- ...{
- VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
- VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
- VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
- },
- ...startParamsEnv
+ ...startParamsEnv,
+ VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
+ VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
+ VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
};

const binFolder = environmentService.isBuilt ? join(environmentService.appRoot, 'bin') : join(environmentService.appRoot, 'resources', 'server', 'bin-dev');
Index: b/src/vs/server/node/remoteTerminalChannel.ts
===================================================================
--- a/src/vs/server/node/remoteTerminalChannel.ts
+++ b/src/vs/server/node/remoteTerminalChannel.ts
@@ -9,6 +9,7 @@ import { cloneAndChange } from '../../ba
import { Disposable } from '../../base/common/lifecycle.js';
import * as path from '../../base/common/path.js';
import * as platform from '../../base/common/platform.js';
+import { removeDangerousEnvVariables } from '../../base/common/processes.js';
import { URI } from '../../base/common/uri.js';
import { IURITransformer } from '../../base/common/uriIpc.js';
import { IServerChannel } from '../../base/parts/ipc/common/ipc.js';
@@ -210,7 +211,9 @@ export class RemoteTerminalChannel exten
};


- const baseEnv = await buildUserEnvironment(args.resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
+ const resolverEnv = { ...args.resolverEnv };
+ removeDangerousEnvVariables(resolverEnv);
+ const baseEnv = await buildUserEnvironment(resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
this._logService.trace('baseEnv', baseEnv);

const reviveWorkspaceFolder = (workspaceData: IWorkspaceFolderData): IWorkspaceFolder => {
Index: b/src/vs/workbench/services/environment/browser/environmentService.ts
===================================================================
--- a/src/vs/workbench/services/environment/browser/environmentService.ts
+++ b/src/vs/workbench/services/environment/browser/environmentService.ts
@@ -302,8 +302,8 @@ export class BrowserWorkbenchEnvironment
extensionDevelopmentKind: undefined
};

- // Fill in selected extra environmental properties
- if (this.payload) {
+ // Extension host development options from the payload are only valid in development builds.
+ if (this.payload && !this.isBuilt) {
for (const [key, value] of this.payload) {
switch (key) {
case 'extensionDevelopmentPath':
47 changes: 47 additions & 0 deletions patches/common/fix-buffer-copy-extensions.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
Always return copies of buffers to extensions

Returns a copied slice of the buffer in extHostCommands instead of
the original backing ArrayBuffer, preventing extensions from mutating
shared memory. Also simplifies webview stream chunk handling to use
VSBuffer.buffer which already returns a safe Uint8Array copy.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61
@finding-id: CVE-2026-47285 GHSA-vcpf-2mpp-vx3v
Index: b/src/vs/workbench/api/common/extHostCommands.ts
===================================================================
--- a/src/vs/workbench/api/common/extHostCommands.ts
+++ b/src/vs/workbench/api/common/extHostCommands.ts
@@ -101,7 +101,8 @@ export class ExtHostCommands implements
return extHostTypeConverter.location.to(obj);
}
if (obj instanceof VSBuffer) {
- return obj.buffer.buffer;
+ // Create a copy of the buffer since the original buffer is owned by the extension host and might be reused for other commands
+ return obj.buffer.buffer.slice(obj.buffer.byteOffset, obj.buffer.byteOffset + obj.buffer.byteLength);
}
if (!Array.isArray(obj)) {
return obj;
Index: b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
===================================================================
--- a/src/vs/workbench/contrib/webview/browser/webviewElement.ts
+++ b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
@@ -820,7 +820,7 @@ export class WebviewElement extends Disp
onData: (chunk) => {
if (!closed) {
try {
- controller.enqueue(new Uint8Array<ArrayBuffer>(chunk.buffer.buffer as ArrayBuffer, chunk.buffer.byteOffset, chunk.buffer.byteLength));
+ controller?.enqueue(new Uint8Array(chunk.buffer));
} catch {
closed = true;
this._activeStreamControllers.delete(controller);
@@ -861,7 +861,7 @@ export class WebviewElement extends Disp
});
listenStream(result.stream, {
onData: (chunk) => {
- const data = new Uint8Array(chunk.buffer.buffer, chunk.buffer.byteOffset, chunk.buffer.byteLength);
+ const data = new Uint8Array(chunk.buffer);
this._send('did-load-resource-chunk', { id, data }, [data.buffer]);
},
onError: () => {
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 114 additions & 0 deletions patches/backported-patches.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -88,5 +88,119 @@
"patch_path": "N/A",
"link": "https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158",
"note": "Notebook Restricted-Mode bypass via mermaid render. Upstream vulnerable file extensions/mermaid-markdown-features/preview-src/notebook/index.ts (the 'temp.innerHTML = result' sink and renderMermaidBlocksInElement) does not exist in this branch's shipped source. The only mermaid extension here, mermaid-chat-features, renders diagrams via escapeHtmlText() into a <pre> and uses textContent (chat-webview-src/mermaidWebview.ts) inside a sandboxed webview with strict nonce CSP - no innerHTML of untrusted content. The markdown-language-features notebook renderer already sanitizes untrusted HTML with DOMPurify. No equivalent vulnerable innerHTML/insertAdjacentHTML sink for untrusted render output exists."
},
{
"finding_id": "CVE-2026-70336",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-fp6w-v29h-43rj",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69320",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-h29r-p8vr-4vfm",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69278",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "GHSA-h9j4-x76r-fvj4",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "CVE-2026-58650",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "GHSA-h6v9-3cqc-v234",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "CVE-2026-47285",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "GHSA-vcpf-2mpp-vx3v",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "CVE-2026-65675",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-3hjg-cwxj-qfc6",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-70335",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-w79w-rj9h-vg4f",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-59113",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "GHSA-36qf-jgq9-4m6j",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "CVE-2026-69306",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
},
{
"finding_id": "GHSA-6xp2-9cj3-f488",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
}
]
109 changes: 109 additions & 0 deletions patches/common/fix-block-privileged-url-payload.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
Block privileged URL payload options in server

Prevents environment variable injection via startParamsEnv by ensuring
VSCODE_* critical vars cannot be overridden, sanitizes resolverEnv before
use in terminal channel, removes dangerous env vars case-insensitively
across all platforms, and restricts extension dev payload options to
non-production builds only.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f
@finding-id: CVE-2026-70336 GHSA-fp6w-v29h-43rj CVE-2026-69320 GHSA-h29r-p8vr-4vfm
Index: b/src/vs/base/common/processes.ts
===================================================================
--- a/src/vs/base/common/processes.ts
+++ b/src/vs/base/common/processes.ts
@@ -3,7 +3,7 @@
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/

-import { IProcessEnvironment, isLinux } from './platform.js';
+import { IProcessEnvironment } from './platform.js';

/**
* Options to be passed to the external program or shell.
@@ -136,13 +136,16 @@ export function removeDangerousEnvVariab
return;
}

- // Unset `DEBUG`, as an invalid value might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/130072
- delete env['DEBUG'];
-
- if (isLinux) {
- // Unset `LD_PRELOAD`, as it might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/134177
- delete env['LD_PRELOAD'];
+ const dangerousEnvVariables = new Set([
+ 'DEBUG',
+ 'NODE_OPTIONS',
+ 'VSCODE_NODE_OPTIONS',
+ 'LD_PRELOAD',
+ 'DYLD_INSERT_LIBRARIES'
+ ]);
+ for (const key of Object.keys(env)) {
+ if (dangerousEnvVariables.has(key.toUpperCase())) {
+ delete env[key];
+ }
}
}
Index: b/src/vs/server/node/extensionHostConnection.ts
===================================================================
--- a/src/vs/server/node/extensionHostConnection.ts
+++ b/src/vs/server/node/extensionHostConnection.ts
@@ -40,12 +40,10 @@ export async function buildUserEnvironme
const env: IProcessEnvironment = {
...processEnv,
...userShellEnv,
- ...{
- VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
- VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
- VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
- },
- ...startParamsEnv
+ ...startParamsEnv,
+ VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
+ VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
+ VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
};

const binFolder = environmentService.isBuilt ? join(environmentService.appRoot, 'bin') : join(environmentService.appRoot, 'resources', 'server', 'bin-dev');
Index: b/src/vs/server/node/remoteTerminalChannel.ts
===================================================================
--- a/src/vs/server/node/remoteTerminalChannel.ts
+++ b/src/vs/server/node/remoteTerminalChannel.ts
@@ -9,6 +9,7 @@ import { cloneAndChange } from '../../ba
import { Disposable } from '../../base/common/lifecycle.js';
import * as path from '../../base/common/path.js';
import * as platform from '../../base/common/platform.js';
+import { removeDangerousEnvVariables } from '../../base/common/processes.js';
import { URI } from '../../base/common/uri.js';
import { IURITransformer } from '../../base/common/uriIpc.js';
import { IServerChannel } from '../../base/parts/ipc/common/ipc.js';
@@ -210,7 +211,9 @@ export class RemoteTerminalChannel exten
};


- const baseEnv = await buildUserEnvironment(args.resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
+ const resolverEnv = { ...args.resolverEnv };
+ removeDangerousEnvVariables(resolverEnv);
+ const baseEnv = await buildUserEnvironment(resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
this._logService.trace('baseEnv', baseEnv);

const reviveWorkspaceFolder = (workspaceData: IWorkspaceFolderData): IWorkspaceFolder => {
Index: b/src/vs/workbench/services/environment/browser/environmentService.ts
===================================================================
--- a/src/vs/workbench/services/environment/browser/environmentService.ts
+++ b/src/vs/workbench/services/environment/browser/environmentService.ts
@@ -302,8 +302,8 @@ export class BrowserWorkbenchEnvironment
extensionDevelopmentKind: undefined
};

- // Fill in selected extra environmental properties
- if (this.payload) {
+ // Extension host development options from the payload are only valid in development builds.
+ if (this.payload && !this.isBuilt) {
for (const [key, value] of this.payload) {
switch (key) {
case 'extensionDevelopmentPath':
47 changes: 47 additions & 0 deletions patches/common/fix-buffer-copy-extensions.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
Always return copies of buffers to extensions

Returns a copied slice of the buffer in extHostCommands instead of
the original backing ArrayBuffer, preventing extensions from mutating
shared memory. Also simplifies webview stream chunk handling to use
VSBuffer.buffer which already returns a safe Uint8Array copy.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61
@finding-id: CVE-2026-47285 GHSA-vcpf-2mpp-vx3v
Index: b/src/vs/workbench/api/common/extHostCommands.ts
===================================================================
--- a/src/vs/workbench/api/common/extHostCommands.ts
+++ b/src/vs/workbench/api/common/extHostCommands.ts
@@ -101,7 +101,8 @@ export class ExtHostCommands implements
return extHostTypeConverter.location.to(obj);
}
if (obj instanceof VSBuffer) {
- return obj.buffer.buffer;
+ // Create a copy of the buffer since the original buffer is owned by the extension host and might be reused for other commands
+ return obj.buffer.buffer.slice(obj.buffer.byteOffset, obj.buffer.byteOffset + obj.buffer.byteLength);
}
if (!Array.isArray(obj)) {
return obj;
Index: b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
===================================================================
--- a/src/vs/workbench/contrib/webview/browser/webviewElement.ts
+++ b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
@@ -820,7 +820,7 @@ export class WebviewElement extends Disp
onData: (chunk) => {
if (!closed) {
try {
- controller.enqueue(new Uint8Array<ArrayBuffer>(chunk.buffer.buffer as ArrayBuffer, chunk.buffer.byteOffset, chunk.buffer.byteLength));
+ controller?.enqueue(new Uint8Array(chunk.buffer));
} catch {
closed = true;
this._activeStreamControllers.delete(controller);
@@ -861,7 +861,7 @@ export class WebviewElement extends Disp
});
listenStream(result.stream, {
onData: (chunk) => {
- const data = new Uint8Array(chunk.buffer.buffer, chunk.buffer.byteOffset, chunk.buffer.byteLength);
+ const data = new Uint8Array(chunk.buffer);
this._send('did-load-resource-chunk', { id, data }, [data.buffer]);
},
onError: () => {
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 114 additions & 0 deletions patches/backported-patches.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -88,5 +88,119 @@
"patch_path": "N/A",
"link": "https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158",
"note": "Notebook Restricted-Mode bypass via mermaid render. Upstream vulnerable file extensions/mermaid-markdown-features/preview-src/notebook/index.ts (the 'temp.innerHTML = result' sink and renderMermaidBlocksInElement) does not exist in this branch's shipped source. The only mermaid extension here, mermaid-chat-features, renders diagrams via escapeHtmlText() into a <pre> and uses textContent (chat-webview-src/mermaidWebview.ts) inside a sandboxed webview with strict nonce CSP - no innerHTML of untrusted content. The markdown-language-features notebook renderer already sanitizes untrusted HTML with DOMPurify. No equivalent vulnerable innerHTML/insertAdjacentHTML sink for untrusted render output exists."
},
{
"finding_id": "CVE-2026-70336",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-fp6w-v29h-43rj",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69320",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-h29r-p8vr-4vfm",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69278",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "GHSA-h9j4-x76r-fvj4",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "CVE-2026-58650",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "GHSA-h6v9-3cqc-v234",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "CVE-2026-47285",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "GHSA-vcpf-2mpp-vx3v",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "CVE-2026-65675",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-3hjg-cwxj-qfc6",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-70335",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-w79w-rj9h-vg4f",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-59113",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "GHSA-36qf-jgq9-4m6j",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "CVE-2026-69306",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
},
{
"finding_id": "GHSA-6xp2-9cj3-f488",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
}
]
109 changes: 109 additions & 0 deletions patches/common/fix-block-privileged-url-payload.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
Block privileged URL payload options in server

Prevents environment variable injection via startParamsEnv by ensuring
VSCODE_* critical vars cannot be overridden, sanitizes resolverEnv before
use in terminal channel, removes dangerous env vars case-insensitively
across all platforms, and restricts extension dev payload options to
non-production builds only.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f
@finding-id: CVE-2026-70336 GHSA-fp6w-v29h-43rj CVE-2026-69320 GHSA-h29r-p8vr-4vfm
Index: b/src/vs/base/common/processes.ts
===================================================================
--- a/src/vs/base/common/processes.ts
+++ b/src/vs/base/common/processes.ts
@@ -3,7 +3,7 @@
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/

-import { IProcessEnvironment, isLinux } from './platform.js';
+import { IProcessEnvironment } from './platform.js';

/**
* Options to be passed to the external program or shell.
@@ -136,13 +136,16 @@ export function removeDangerousEnvVariab
return;
}

- // Unset `DEBUG`, as an invalid value might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/130072
- delete env['DEBUG'];
-
- if (isLinux) {
- // Unset `LD_PRELOAD`, as it might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/134177
- delete env['LD_PRELOAD'];
+ const dangerousEnvVariables = new Set([
+ 'DEBUG',
+ 'NODE_OPTIONS',
+ 'VSCODE_NODE_OPTIONS',
+ 'LD_PRELOAD',
+ 'DYLD_INSERT_LIBRARIES'
+ ]);
+ for (const key of Object.keys(env)) {
+ if (dangerousEnvVariables.has(key.toUpperCase())) {
+ delete env[key];
+ }
}
}
Index: b/src/vs/server/node/extensionHostConnection.ts
===================================================================
--- a/src/vs/server/node/extensionHostConnection.ts
+++ b/src/vs/server/node/extensionHostConnection.ts
@@ -40,12 +40,10 @@ export async function buildUserEnvironme
const env: IProcessEnvironment = {
...processEnv,
...userShellEnv,
- ...{
- VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
- VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
- VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
- },
- ...startParamsEnv
+ ...startParamsEnv,
+ VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
+ VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
+ VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
};

const binFolder = environmentService.isBuilt ? join(environmentService.appRoot, 'bin') : join(environmentService.appRoot, 'resources', 'server', 'bin-dev');
Index: b/src/vs/server/node/remoteTerminalChannel.ts
===================================================================
--- a/src/vs/server/node/remoteTerminalChannel.ts
+++ b/src/vs/server/node/remoteTerminalChannel.ts
@@ -9,6 +9,7 @@ import { cloneAndChange } from '../../ba
import { Disposable } from '../../base/common/lifecycle.js';
import * as path from '../../base/common/path.js';
import * as platform from '../../base/common/platform.js';
+import { removeDangerousEnvVariables } from '../../base/common/processes.js';
import { URI } from '../../base/common/uri.js';
import { IURITransformer } from '../../base/common/uriIpc.js';
import { IServerChannel } from '../../base/parts/ipc/common/ipc.js';
@@ -210,7 +211,9 @@ export class RemoteTerminalChannel exten
};


- const baseEnv = await buildUserEnvironment(args.resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
+ const resolverEnv = { ...args.resolverEnv };
+ removeDangerousEnvVariables(resolverEnv);
+ const baseEnv = await buildUserEnvironment(resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
this._logService.trace('baseEnv', baseEnv);

const reviveWorkspaceFolder = (workspaceData: IWorkspaceFolderData): IWorkspaceFolder => {
Index: b/src/vs/workbench/services/environment/browser/environmentService.ts
===================================================================
--- a/src/vs/workbench/services/environment/browser/environmentService.ts
+++ b/src/vs/workbench/services/environment/browser/environmentService.ts
@@ -302,8 +302,8 @@ export class BrowserWorkbenchEnvironment
extensionDevelopmentKind: undefined
};

- // Fill in selected extra environmental properties
- if (this.payload) {
+ // Extension host development options from the payload are only valid in development builds.
+ if (this.payload && !this.isBuilt) {
for (const [key, value] of this.payload) {
switch (key) {
case 'extensionDevelopmentPath':
47 changes: 47 additions & 0 deletions patches/common/fix-buffer-copy-extensions.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
Always return copies of buffers to extensions

Returns a copied slice of the buffer in extHostCommands instead of
the original backing ArrayBuffer, preventing extensions from mutating
shared memory. Also simplifies webview stream chunk handling to use
VSBuffer.buffer which already returns a safe Uint8Array copy.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61
@finding-id: CVE-2026-47285 GHSA-vcpf-2mpp-vx3v
Index: b/src/vs/workbench/api/common/extHostCommands.ts
===================================================================
--- a/src/vs/workbench/api/common/extHostCommands.ts
+++ b/src/vs/workbench/api/common/extHostCommands.ts
@@ -101,7 +101,8 @@ export class ExtHostCommands implements
return extHostTypeConverter.location.to(obj);
}
if (obj instanceof VSBuffer) {
- return obj.buffer.buffer;
+ // Create a copy of the buffer since the original buffer is owned by the extension host and might be reused for other commands
+ return obj.buffer.buffer.slice(obj.buffer.byteOffset, obj.buffer.byteOffset + obj.buffer.byteLength);
}
if (!Array.isArray(obj)) {
return obj;
Index: b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
===================================================================
--- a/src/vs/workbench/contrib/webview/browser/webviewElement.ts
+++ b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
@@ -820,7 +820,7 @@ export class WebviewElement extends Disp
onData: (chunk) => {
if (!closed) {
try {
- controller.enqueue(new Uint8Array<ArrayBuffer>(chunk.buffer.buffer as ArrayBuffer, chunk.buffer.byteOffset, chunk.buffer.byteLength));
+ controller?.enqueue(new Uint8Array(chunk.buffer));
} catch {
closed = true;
this._activeStreamControllers.delete(controller);
@@ -861,7 +861,7 @@ export class WebviewElement extends Disp
});
listenStream(result.stream, {
onData: (chunk) => {
- const data = new Uint8Array(chunk.buffer.buffer, chunk.buffer.byteOffset, chunk.buffer.byteLength);
+ const data = new Uint8Array(chunk.buffer);
this._send('did-load-resource-chunk', { id, data }, [data.buffer]);
},
onError: () => {
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 114 additions & 0 deletions patches/backported-patches.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -88,5 +88,119 @@
"patch_path": "N/A",
"link": "https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158",
"note": "Notebook Restricted-Mode bypass via mermaid render. Upstream vulnerable file extensions/mermaid-markdown-features/preview-src/notebook/index.ts (the 'temp.innerHTML = result' sink and renderMermaidBlocksInElement) does not exist in this branch's shipped source. The only mermaid extension here, mermaid-chat-features, renders diagrams via escapeHtmlText() into a <pre> and uses textContent (chat-webview-src/mermaidWebview.ts) inside a sandboxed webview with strict nonce CSP - no innerHTML of untrusted content. The markdown-language-features notebook renderer already sanitizes untrusted HTML with DOMPurify. No equivalent vulnerable innerHTML/insertAdjacentHTML sink for untrusted render output exists."
},
{
"finding_id": "CVE-2026-70336",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-fp6w-v29h-43rj",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69320",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-h29r-p8vr-4vfm",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69278",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "GHSA-h9j4-x76r-fvj4",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "CVE-2026-58650",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "GHSA-h6v9-3cqc-v234",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "CVE-2026-47285",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "GHSA-vcpf-2mpp-vx3v",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "CVE-2026-65675",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-3hjg-cwxj-qfc6",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-70335",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-w79w-rj9h-vg4f",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-59113",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "GHSA-36qf-jgq9-4m6j",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "CVE-2026-69306",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
},
{
"finding_id": "GHSA-6xp2-9cj3-f488",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
}
]
109 changes: 109 additions & 0 deletions patches/common/fix-block-privileged-url-payload.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
Block privileged URL payload options in server

Prevents environment variable injection via startParamsEnv by ensuring
VSCODE_* critical vars cannot be overridden, sanitizes resolverEnv before
use in terminal channel, removes dangerous env vars case-insensitively
across all platforms, and restricts extension dev payload options to
non-production builds only.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f
@finding-id: CVE-2026-70336 GHSA-fp6w-v29h-43rj CVE-2026-69320 GHSA-h29r-p8vr-4vfm
Index: b/src/vs/base/common/processes.ts
===================================================================
--- a/src/vs/base/common/processes.ts
+++ b/src/vs/base/common/processes.ts
@@ -3,7 +3,7 @@
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/

-import { IProcessEnvironment, isLinux } from './platform.js';
+import { IProcessEnvironment } from './platform.js';

/**
* Options to be passed to the external program or shell.
@@ -136,13 +136,16 @@ export function removeDangerousEnvVariab
return;
}

- // Unset `DEBUG`, as an invalid value might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/130072
- delete env['DEBUG'];
-
- if (isLinux) {
- // Unset `LD_PRELOAD`, as it might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/134177
- delete env['LD_PRELOAD'];
+ const dangerousEnvVariables = new Set([
+ 'DEBUG',
+ 'NODE_OPTIONS',
+ 'VSCODE_NODE_OPTIONS',
+ 'LD_PRELOAD',
+ 'DYLD_INSERT_LIBRARIES'
+ ]);
+ for (const key of Object.keys(env)) {
+ if (dangerousEnvVariables.has(key.toUpperCase())) {
+ delete env[key];
+ }
}
}
Index: b/src/vs/server/node/extensionHostConnection.ts
===================================================================
--- a/src/vs/server/node/extensionHostConnection.ts
+++ b/src/vs/server/node/extensionHostConnection.ts
@@ -40,12 +40,10 @@ export async function buildUserEnvironme
const env: IProcessEnvironment = {
...processEnv,
...userShellEnv,
- ...{
- VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
- VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
- VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
- },
- ...startParamsEnv
+ ...startParamsEnv,
+ VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
+ VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
+ VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
};

const binFolder = environmentService.isBuilt ? join(environmentService.appRoot, 'bin') : join(environmentService.appRoot, 'resources', 'server', 'bin-dev');
Index: b/src/vs/server/node/remoteTerminalChannel.ts
===================================================================
--- a/src/vs/server/node/remoteTerminalChannel.ts
+++ b/src/vs/server/node/remoteTerminalChannel.ts
@@ -9,6 +9,7 @@ import { cloneAndChange } from '../../ba
import { Disposable } from '../../base/common/lifecycle.js';
import * as path from '../../base/common/path.js';
import * as platform from '../../base/common/platform.js';
+import { removeDangerousEnvVariables } from '../../base/common/processes.js';
import { URI } from '../../base/common/uri.js';
import { IURITransformer } from '../../base/common/uriIpc.js';
import { IServerChannel } from '../../base/parts/ipc/common/ipc.js';
@@ -210,7 +211,9 @@ export class RemoteTerminalChannel exten
};


- const baseEnv = await buildUserEnvironment(args.resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
+ const resolverEnv = { ...args.resolverEnv };
+ removeDangerousEnvVariables(resolverEnv);
+ const baseEnv = await buildUserEnvironment(resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
this._logService.trace('baseEnv', baseEnv);

const reviveWorkspaceFolder = (workspaceData: IWorkspaceFolderData): IWorkspaceFolder => {
Index: b/src/vs/workbench/services/environment/browser/environmentService.ts
===================================================================
--- a/src/vs/workbench/services/environment/browser/environmentService.ts
+++ b/src/vs/workbench/services/environment/browser/environmentService.ts
@@ -302,8 +302,8 @@ export class BrowserWorkbenchEnvironment
extensionDevelopmentKind: undefined
};

- // Fill in selected extra environmental properties
- if (this.payload) {
+ // Extension host development options from the payload are only valid in development builds.
+ if (this.payload && !this.isBuilt) {
for (const [key, value] of this.payload) {
switch (key) {
case 'extensionDevelopmentPath':
47 changes: 47 additions & 0 deletions patches/common/fix-buffer-copy-extensions.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
Always return copies of buffers to extensions

Returns a copied slice of the buffer in extHostCommands instead of
the original backing ArrayBuffer, preventing extensions from mutating
shared memory. Also simplifies webview stream chunk handling to use
VSBuffer.buffer which already returns a safe Uint8Array copy.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61
@finding-id: CVE-2026-47285 GHSA-vcpf-2mpp-vx3v
Index: b/src/vs/workbench/api/common/extHostCommands.ts
===================================================================
--- a/src/vs/workbench/api/common/extHostCommands.ts
+++ b/src/vs/workbench/api/common/extHostCommands.ts
@@ -101,7 +101,8 @@ export class ExtHostCommands implements
return extHostTypeConverter.location.to(obj);
}
if (obj instanceof VSBuffer) {
- return obj.buffer.buffer;
+ // Create a copy of the buffer since the original buffer is owned by the extension host and might be reused for other commands
+ return obj.buffer.buffer.slice(obj.buffer.byteOffset, obj.buffer.byteOffset + obj.buffer.byteLength);
}
if (!Array.isArray(obj)) {
return obj;
Index: b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
===================================================================
--- a/src/vs/workbench/contrib/webview/browser/webviewElement.ts
+++ b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
@@ -820,7 +820,7 @@ export class WebviewElement extends Disp
onData: (chunk) => {
if (!closed) {
try {
- controller.enqueue(new Uint8Array<ArrayBuffer>(chunk.buffer.buffer as ArrayBuffer, chunk.buffer.byteOffset, chunk.buffer.byteLength));
+ controller?.enqueue(new Uint8Array(chunk.buffer));
} catch {
closed = true;
this._activeStreamControllers.delete(controller);
@@ -861,7 +861,7 @@ export class WebviewElement extends Disp
});
listenStream(result.stream, {
onData: (chunk) => {
- const data = new Uint8Array(chunk.buffer.buffer, chunk.buffer.byteOffset, chunk.buffer.byteLength);
+ const data = new Uint8Array(chunk.buffer);
this._send('did-load-resource-chunk', { id, data }, [data.buffer]);
},
onError: () => {
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 114 additions & 0 deletions patches/backported-patches.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -88,5 +88,119 @@
"patch_path": "N/A",
"link": "https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158",
"note": "Notebook Restricted-Mode bypass via mermaid render. Upstream vulnerable file extensions/mermaid-markdown-features/preview-src/notebook/index.ts (the 'temp.innerHTML = result' sink and renderMermaidBlocksInElement) does not exist in this branch's shipped source. The only mermaid extension here, mermaid-chat-features, renders diagrams via escapeHtmlText() into a <pre> and uses textContent (chat-webview-src/mermaidWebview.ts) inside a sandboxed webview with strict nonce CSP - no innerHTML of untrusted content. The markdown-language-features notebook renderer already sanitizes untrusted HTML with DOMPurify. No equivalent vulnerable innerHTML/insertAdjacentHTML sink for untrusted render output exists."
},
{
"finding_id": "CVE-2026-70336",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-fp6w-v29h-43rj",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69320",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-h29r-p8vr-4vfm",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69278",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "GHSA-h9j4-x76r-fvj4",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "CVE-2026-58650",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "GHSA-h6v9-3cqc-v234",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "CVE-2026-47285",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "GHSA-vcpf-2mpp-vx3v",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "CVE-2026-65675",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-3hjg-cwxj-qfc6",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-70335",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-w79w-rj9h-vg4f",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-59113",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "GHSA-36qf-jgq9-4m6j",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "CVE-2026-69306",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
},
{
"finding_id": "GHSA-6xp2-9cj3-f488",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
}
]
109 changes: 109 additions & 0 deletions patches/common/fix-block-privileged-url-payload.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
Block privileged URL payload options in server

Prevents environment variable injection via startParamsEnv by ensuring
VSCODE_* critical vars cannot be overridden, sanitizes resolverEnv before
use in terminal channel, removes dangerous env vars case-insensitively
across all platforms, and restricts extension dev payload options to
non-production builds only.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f
@finding-id: CVE-2026-70336 GHSA-fp6w-v29h-43rj CVE-2026-69320 GHSA-h29r-p8vr-4vfm
Index: b/src/vs/base/common/processes.ts
===================================================================
--- a/src/vs/base/common/processes.ts
+++ b/src/vs/base/common/processes.ts
@@ -3,7 +3,7 @@
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/

-import { IProcessEnvironment, isLinux } from './platform.js';
+import { IProcessEnvironment } from './platform.js';

/**
* Options to be passed to the external program or shell.
@@ -136,13 +136,16 @@ export function removeDangerousEnvVariab
return;
}

- // Unset `DEBUG`, as an invalid value might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/130072
- delete env['DEBUG'];
-
- if (isLinux) {
- // Unset `LD_PRELOAD`, as it might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/134177
- delete env['LD_PRELOAD'];
+ const dangerousEnvVariables = new Set([
+ 'DEBUG',
+ 'NODE_OPTIONS',
+ 'VSCODE_NODE_OPTIONS',
+ 'LD_PRELOAD',
+ 'DYLD_INSERT_LIBRARIES'
+ ]);
+ for (const key of Object.keys(env)) {
+ if (dangerousEnvVariables.has(key.toUpperCase())) {
+ delete env[key];
+ }
}
}
Index: b/src/vs/server/node/extensionHostConnection.ts
===================================================================
--- a/src/vs/server/node/extensionHostConnection.ts
+++ b/src/vs/server/node/extensionHostConnection.ts
@@ -40,12 +40,10 @@ export async function buildUserEnvironme
const env: IProcessEnvironment = {
...processEnv,
...userShellEnv,
- ...{
- VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
- VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
- VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
- },
- ...startParamsEnv
+ ...startParamsEnv,
+ VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
+ VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
+ VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
};

const binFolder = environmentService.isBuilt ? join(environmentService.appRoot, 'bin') : join(environmentService.appRoot, 'resources', 'server', 'bin-dev');
Index: b/src/vs/server/node/remoteTerminalChannel.ts
===================================================================
--- a/src/vs/server/node/remoteTerminalChannel.ts
+++ b/src/vs/server/node/remoteTerminalChannel.ts
@@ -9,6 +9,7 @@ import { cloneAndChange } from '../../ba
import { Disposable } from '../../base/common/lifecycle.js';
import * as path from '../../base/common/path.js';
import * as platform from '../../base/common/platform.js';
+import { removeDangerousEnvVariables } from '../../base/common/processes.js';
import { URI } from '../../base/common/uri.js';
import { IURITransformer } from '../../base/common/uriIpc.js';
import { IServerChannel } from '../../base/parts/ipc/common/ipc.js';
@@ -210,7 +211,9 @@ export class RemoteTerminalChannel exten
};


- const baseEnv = await buildUserEnvironment(args.resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
+ const resolverEnv = { ...args.resolverEnv };
+ removeDangerousEnvVariables(resolverEnv);
+ const baseEnv = await buildUserEnvironment(resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
this._logService.trace('baseEnv', baseEnv);

const reviveWorkspaceFolder = (workspaceData: IWorkspaceFolderData): IWorkspaceFolder => {
Index: b/src/vs/workbench/services/environment/browser/environmentService.ts
===================================================================
--- a/src/vs/workbench/services/environment/browser/environmentService.ts
+++ b/src/vs/workbench/services/environment/browser/environmentService.ts
@@ -302,8 +302,8 @@ export class BrowserWorkbenchEnvironment
extensionDevelopmentKind: undefined
};

- // Fill in selected extra environmental properties
- if (this.payload) {
+ // Extension host development options from the payload are only valid in development builds.
+ if (this.payload && !this.isBuilt) {
for (const [key, value] of this.payload) {
switch (key) {
case 'extensionDevelopmentPath':
47 changes: 47 additions & 0 deletions patches/common/fix-buffer-copy-extensions.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
Always return copies of buffers to extensions

Returns a copied slice of the buffer in extHostCommands instead of
the original backing ArrayBuffer, preventing extensions from mutating
shared memory. Also simplifies webview stream chunk handling to use
VSBuffer.buffer which already returns a safe Uint8Array copy.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61
@finding-id: CVE-2026-47285 GHSA-vcpf-2mpp-vx3v
Index: b/src/vs/workbench/api/common/extHostCommands.ts
===================================================================
--- a/src/vs/workbench/api/common/extHostCommands.ts
+++ b/src/vs/workbench/api/common/extHostCommands.ts
@@ -101,7 +101,8 @@ export class ExtHostCommands implements
return extHostTypeConverter.location.to(obj);
}
if (obj instanceof VSBuffer) {
- return obj.buffer.buffer;
+ // Create a copy of the buffer since the original buffer is owned by the extension host and might be reused for other commands
+ return obj.buffer.buffer.slice(obj.buffer.byteOffset, obj.buffer.byteOffset + obj.buffer.byteLength);
}
if (!Array.isArray(obj)) {
return obj;
Index: b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
===================================================================
--- a/src/vs/workbench/contrib/webview/browser/webviewElement.ts
+++ b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
@@ -820,7 +820,7 @@ export class WebviewElement extends Disp
onData: (chunk) => {
if (!closed) {
try {
- controller.enqueue(new Uint8Array<ArrayBuffer>(chunk.buffer.buffer as ArrayBuffer, chunk.buffer.byteOffset, chunk.buffer.byteLength));
+ controller?.enqueue(new Uint8Array(chunk.buffer));
} catch {
closed = true;
this._activeStreamControllers.delete(controller);
@@ -861,7 +861,7 @@ export class WebviewElement extends Disp
});
listenStream(result.stream, {
onData: (chunk) => {
- const data = new Uint8Array(chunk.buffer.buffer, chunk.buffer.byteOffset, chunk.buffer.byteLength);
+ const data = new Uint8Array(chunk.buffer);
this._send('did-load-resource-chunk', { id, data }, [data.buffer]);
},
onError: () => {
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 114 additions & 0 deletions patches/backported-patches.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -88,5 +88,119 @@
"patch_path": "N/A",
"link": "https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158",
"note": "Notebook Restricted-Mode bypass via mermaid render. Upstream vulnerable file extensions/mermaid-markdown-features/preview-src/notebook/index.ts (the 'temp.innerHTML = result' sink and renderMermaidBlocksInElement) does not exist in this branch's shipped source. The only mermaid extension here, mermaid-chat-features, renders diagrams via escapeHtmlText() into a <pre> and uses textContent (chat-webview-src/mermaidWebview.ts) inside a sandboxed webview with strict nonce CSP - no innerHTML of untrusted content. The markdown-language-features notebook renderer already sanitizes untrusted HTML with DOMPurify. No equivalent vulnerable innerHTML/insertAdjacentHTML sink for untrusted render output exists."
},
{
"finding_id": "CVE-2026-70336",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-fp6w-v29h-43rj",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69320",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-h29r-p8vr-4vfm",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69278",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "GHSA-h9j4-x76r-fvj4",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "CVE-2026-58650",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "GHSA-h6v9-3cqc-v234",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "CVE-2026-47285",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "GHSA-vcpf-2mpp-vx3v",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "CVE-2026-65675",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-3hjg-cwxj-qfc6",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-70335",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-w79w-rj9h-vg4f",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-59113",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "GHSA-36qf-jgq9-4m6j",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "CVE-2026-69306",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
},
{
"finding_id": "GHSA-6xp2-9cj3-f488",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
}
]
109 changes: 109 additions & 0 deletions patches/common/fix-block-privileged-url-payload.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
Block privileged URL payload options in server

Prevents environment variable injection via startParamsEnv by ensuring
VSCODE_* critical vars cannot be overridden, sanitizes resolverEnv before
use in terminal channel, removes dangerous env vars case-insensitively
across all platforms, and restricts extension dev payload options to
non-production builds only.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f
@finding-id: CVE-2026-70336 GHSA-fp6w-v29h-43rj CVE-2026-69320 GHSA-h29r-p8vr-4vfm
Index: b/src/vs/base/common/processes.ts
===================================================================
--- a/src/vs/base/common/processes.ts
+++ b/src/vs/base/common/processes.ts
@@ -3,7 +3,7 @@
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/

-import { IProcessEnvironment, isLinux } from './platform.js';
+import { IProcessEnvironment } from './platform.js';

/**
* Options to be passed to the external program or shell.
@@ -136,13 +136,16 @@ export function removeDangerousEnvVariab
return;
}

- // Unset `DEBUG`, as an invalid value might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/130072
- delete env['DEBUG'];
-
- if (isLinux) {
- // Unset `LD_PRELOAD`, as it might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/134177
- delete env['LD_PRELOAD'];
+ const dangerousEnvVariables = new Set([
+ 'DEBUG',
+ 'NODE_OPTIONS',
+ 'VSCODE_NODE_OPTIONS',
+ 'LD_PRELOAD',
+ 'DYLD_INSERT_LIBRARIES'
+ ]);
+ for (const key of Object.keys(env)) {
+ if (dangerousEnvVariables.has(key.toUpperCase())) {
+ delete env[key];
+ }
}
}
Index: b/src/vs/server/node/extensionHostConnection.ts
===================================================================
--- a/src/vs/server/node/extensionHostConnection.ts
+++ b/src/vs/server/node/extensionHostConnection.ts
@@ -40,12 +40,10 @@ export async function buildUserEnvironme
const env: IProcessEnvironment = {
...processEnv,
...userShellEnv,
- ...{
- VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
- VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
- VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
- },
- ...startParamsEnv
+ ...startParamsEnv,
+ VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
+ VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
+ VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
};

const binFolder = environmentService.isBuilt ? join(environmentService.appRoot, 'bin') : join(environmentService.appRoot, 'resources', 'server', 'bin-dev');
Index: b/src/vs/server/node/remoteTerminalChannel.ts
===================================================================
--- a/src/vs/server/node/remoteTerminalChannel.ts
+++ b/src/vs/server/node/remoteTerminalChannel.ts
@@ -9,6 +9,7 @@ import { cloneAndChange } from '../../ba
import { Disposable } from '../../base/common/lifecycle.js';
import * as path from '../../base/common/path.js';
import * as platform from '../../base/common/platform.js';
+import { removeDangerousEnvVariables } from '../../base/common/processes.js';
import { URI } from '../../base/common/uri.js';
import { IURITransformer } from '../../base/common/uriIpc.js';
import { IServerChannel } from '../../base/parts/ipc/common/ipc.js';
@@ -210,7 +211,9 @@ export class RemoteTerminalChannel exten
};


- const baseEnv = await buildUserEnvironment(args.resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
+ const resolverEnv = { ...args.resolverEnv };
+ removeDangerousEnvVariables(resolverEnv);
+ const baseEnv = await buildUserEnvironment(resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
this._logService.trace('baseEnv', baseEnv);

const reviveWorkspaceFolder = (workspaceData: IWorkspaceFolderData): IWorkspaceFolder => {
Index: b/src/vs/workbench/services/environment/browser/environmentService.ts
===================================================================
--- a/src/vs/workbench/services/environment/browser/environmentService.ts
+++ b/src/vs/workbench/services/environment/browser/environmentService.ts
@@ -302,8 +302,8 @@ export class BrowserWorkbenchEnvironment
extensionDevelopmentKind: undefined
};

- // Fill in selected extra environmental properties
- if (this.payload) {
+ // Extension host development options from the payload are only valid in development builds.
+ if (this.payload && !this.isBuilt) {
for (const [key, value] of this.payload) {
switch (key) {
case 'extensionDevelopmentPath':
47 changes: 47 additions & 0 deletions patches/common/fix-buffer-copy-extensions.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
Always return copies of buffers to extensions

Returns a copied slice of the buffer in extHostCommands instead of
the original backing ArrayBuffer, preventing extensions from mutating
shared memory. Also simplifies webview stream chunk handling to use
VSBuffer.buffer which already returns a safe Uint8Array copy.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61
@finding-id: CVE-2026-47285 GHSA-vcpf-2mpp-vx3v
Index: b/src/vs/workbench/api/common/extHostCommands.ts
===================================================================
--- a/src/vs/workbench/api/common/extHostCommands.ts
+++ b/src/vs/workbench/api/common/extHostCommands.ts
@@ -101,7 +101,8 @@ export class ExtHostCommands implements
return extHostTypeConverter.location.to(obj);
}
if (obj instanceof VSBuffer) {
- return obj.buffer.buffer;
+ // Create a copy of the buffer since the original buffer is owned by the extension host and might be reused for other commands
+ return obj.buffer.buffer.slice(obj.buffer.byteOffset, obj.buffer.byteOffset + obj.buffer.byteLength);
}
if (!Array.isArray(obj)) {
return obj;
Index: b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
===================================================================
--- a/src/vs/workbench/contrib/webview/browser/webviewElement.ts
+++ b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
@@ -820,7 +820,7 @@ export class WebviewElement extends Disp
onData: (chunk) => {
if (!closed) {
try {
- controller.enqueue(new Uint8Array<ArrayBuffer>(chunk.buffer.buffer as ArrayBuffer, chunk.buffer.byteOffset, chunk.buffer.byteLength));
+ controller?.enqueue(new Uint8Array(chunk.buffer));
} catch {
closed = true;
this._activeStreamControllers.delete(controller);
@@ -861,7 +861,7 @@ export class WebviewElement extends Disp
});
listenStream(result.stream, {
onData: (chunk) => {
- const data = new Uint8Array(chunk.buffer.buffer, chunk.buffer.byteOffset, chunk.buffer.byteLength);
+ const data = new Uint8Array(chunk.buffer);
this._send('did-load-resource-chunk', { id, data }, [data.buffer]);
},
onError: () => {
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 114 additions & 0 deletions patches/backported-patches.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -88,5 +88,119 @@
"patch_path": "N/A",
"link": "https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158",
"note": "Notebook Restricted-Mode bypass via mermaid render. Upstream vulnerable file extensions/mermaid-markdown-features/preview-src/notebook/index.ts (the 'temp.innerHTML = result' sink and renderMermaidBlocksInElement) does not exist in this branch's shipped source. The only mermaid extension here, mermaid-chat-features, renders diagrams via escapeHtmlText() into a <pre> and uses textContent (chat-webview-src/mermaidWebview.ts) inside a sandboxed webview with strict nonce CSP - no innerHTML of untrusted content. The markdown-language-features notebook renderer already sanitizes untrusted HTML with DOMPurify. No equivalent vulnerable innerHTML/insertAdjacentHTML sink for untrusted render output exists."
},
{
"finding_id": "CVE-2026-70336",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-fp6w-v29h-43rj",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69320",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-h29r-p8vr-4vfm",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69278",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "GHSA-h9j4-x76r-fvj4",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "CVE-2026-58650",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "GHSA-h6v9-3cqc-v234",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "CVE-2026-47285",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "GHSA-vcpf-2mpp-vx3v",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "CVE-2026-65675",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-3hjg-cwxj-qfc6",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-70335",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-w79w-rj9h-vg4f",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-59113",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "GHSA-36qf-jgq9-4m6j",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "CVE-2026-69306",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
},
{
"finding_id": "GHSA-6xp2-9cj3-f488",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
}
]
109 changes: 109 additions & 0 deletions patches/common/fix-block-privileged-url-payload.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
Block privileged URL payload options in server

Prevents environment variable injection via startParamsEnv by ensuring
VSCODE_* critical vars cannot be overridden, sanitizes resolverEnv before
use in terminal channel, removes dangerous env vars case-insensitively
across all platforms, and restricts extension dev payload options to
non-production builds only.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f
@finding-id: CVE-2026-70336 GHSA-fp6w-v29h-43rj CVE-2026-69320 GHSA-h29r-p8vr-4vfm
Index: b/src/vs/base/common/processes.ts
===================================================================
--- a/src/vs/base/common/processes.ts
+++ b/src/vs/base/common/processes.ts
@@ -3,7 +3,7 @@
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/

-import { IProcessEnvironment, isLinux } from './platform.js';
+import { IProcessEnvironment } from './platform.js';

/**
* Options to be passed to the external program or shell.
@@ -136,13 +136,16 @@ export function removeDangerousEnvVariab
return;
}

- // Unset `DEBUG`, as an invalid value might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/130072
- delete env['DEBUG'];
-
- if (isLinux) {
- // Unset `LD_PRELOAD`, as it might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/134177
- delete env['LD_PRELOAD'];
+ const dangerousEnvVariables = new Set([
+ 'DEBUG',
+ 'NODE_OPTIONS',
+ 'VSCODE_NODE_OPTIONS',
+ 'LD_PRELOAD',
+ 'DYLD_INSERT_LIBRARIES'
+ ]);
+ for (const key of Object.keys(env)) {
+ if (dangerousEnvVariables.has(key.toUpperCase())) {
+ delete env[key];
+ }
}
}
Index: b/src/vs/server/node/extensionHostConnection.ts
===================================================================
--- a/src/vs/server/node/extensionHostConnection.ts
+++ b/src/vs/server/node/extensionHostConnection.ts
@@ -40,12 +40,10 @@ export async function buildUserEnvironme
const env: IProcessEnvironment = {
...processEnv,
...userShellEnv,
- ...{
- VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
- VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
- VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
- },
- ...startParamsEnv
+ ...startParamsEnv,
+ VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
+ VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
+ VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
};

const binFolder = environmentService.isBuilt ? join(environmentService.appRoot, 'bin') : join(environmentService.appRoot, 'resources', 'server', 'bin-dev');
Index: b/src/vs/server/node/remoteTerminalChannel.ts
===================================================================
--- a/src/vs/server/node/remoteTerminalChannel.ts
+++ b/src/vs/server/node/remoteTerminalChannel.ts
@@ -9,6 +9,7 @@ import { cloneAndChange } from '../../ba
import { Disposable } from '../../base/common/lifecycle.js';
import * as path from '../../base/common/path.js';
import * as platform from '../../base/common/platform.js';
+import { removeDangerousEnvVariables } from '../../base/common/processes.js';
import { URI } from '../../base/common/uri.js';
import { IURITransformer } from '../../base/common/uriIpc.js';
import { IServerChannel } from '../../base/parts/ipc/common/ipc.js';
@@ -210,7 +211,9 @@ export class RemoteTerminalChannel exten
};


- const baseEnv = await buildUserEnvironment(args.resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
+ const resolverEnv = { ...args.resolverEnv };
+ removeDangerousEnvVariables(resolverEnv);
+ const baseEnv = await buildUserEnvironment(resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
this._logService.trace('baseEnv', baseEnv);

const reviveWorkspaceFolder = (workspaceData: IWorkspaceFolderData): IWorkspaceFolder => {
Index: b/src/vs/workbench/services/environment/browser/environmentService.ts
===================================================================
--- a/src/vs/workbench/services/environment/browser/environmentService.ts
+++ b/src/vs/workbench/services/environment/browser/environmentService.ts
@@ -302,8 +302,8 @@ export class BrowserWorkbenchEnvironment
extensionDevelopmentKind: undefined
};

- // Fill in selected extra environmental properties
- if (this.payload) {
+ // Extension host development options from the payload are only valid in development builds.
+ if (this.payload && !this.isBuilt) {
for (const [key, value] of this.payload) {
switch (key) {
case 'extensionDevelopmentPath':
47 changes: 47 additions & 0 deletions patches/common/fix-buffer-copy-extensions.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
Always return copies of buffers to extensions

Returns a copied slice of the buffer in extHostCommands instead of
the original backing ArrayBuffer, preventing extensions from mutating
shared memory. Also simplifies webview stream chunk handling to use
VSBuffer.buffer which already returns a safe Uint8Array copy.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61
@finding-id: CVE-2026-47285 GHSA-vcpf-2mpp-vx3v
Index: b/src/vs/workbench/api/common/extHostCommands.ts
===================================================================
--- a/src/vs/workbench/api/common/extHostCommands.ts
+++ b/src/vs/workbench/api/common/extHostCommands.ts
@@ -101,7 +101,8 @@ export class ExtHostCommands implements
return extHostTypeConverter.location.to(obj);
}
if (obj instanceof VSBuffer) {
- return obj.buffer.buffer;
+ // Create a copy of the buffer since the original buffer is owned by the extension host and might be reused for other commands
+ return obj.buffer.buffer.slice(obj.buffer.byteOffset, obj.buffer.byteOffset + obj.buffer.byteLength);
}
if (!Array.isArray(obj)) {
return obj;
Index: b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
===================================================================
--- a/src/vs/workbench/contrib/webview/browser/webviewElement.ts
+++ b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
@@ -820,7 +820,7 @@ export class WebviewElement extends Disp
onData: (chunk) => {
if (!closed) {
try {
- controller.enqueue(new Uint8Array<ArrayBuffer>(chunk.buffer.buffer as ArrayBuffer, chunk.buffer.byteOffset, chunk.buffer.byteLength));
+ controller?.enqueue(new Uint8Array(chunk.buffer));
} catch {
closed = true;
this._activeStreamControllers.delete(controller);
@@ -861,7 +861,7 @@ export class WebviewElement extends Disp
});
listenStream(result.stream, {
onData: (chunk) => {
- const data = new Uint8Array(chunk.buffer.buffer, chunk.buffer.byteOffset, chunk.buffer.byteLength);
+ const data = new Uint8Array(chunk.buffer);
this._send('did-load-resource-chunk', { id, data }, [data.buffer]);
},
onError: () => {
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 114 additions & 0 deletions patches/backported-patches.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -88,5 +88,119 @@
"patch_path": "N/A",
"link": "https://github.com/microsoft/vscode/commit/bc2d56c6f8da22a4bd31f741fcb034208770f158",
"note": "Notebook Restricted-Mode bypass via mermaid render. Upstream vulnerable file extensions/mermaid-markdown-features/preview-src/notebook/index.ts (the 'temp.innerHTML = result' sink and renderMermaidBlocksInElement) does not exist in this branch's shipped source. The only mermaid extension here, mermaid-chat-features, renders diagrams via escapeHtmlText() into a <pre> and uses textContent (chat-webview-src/mermaidWebview.ts) inside a sandboxed webview with strict nonce CSP - no innerHTML of untrusted content. The markdown-language-features notebook renderer already sanitizes untrusted HTML with DOMPurify. No equivalent vulnerable innerHTML/insertAdjacentHTML sink for untrusted render output exists."
},
{
"finding_id": "CVE-2026-70336",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-fp6w-v29h-43rj",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69320",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "GHSA-h29r-p8vr-4vfm",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-block-privileged-url-payload.diff",
"link": "https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f"
},
{
"finding_id": "CVE-2026-69278",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "GHSA-h9j4-x76r-fvj4",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-terminal-workspace-trust-bypass.diff",
"link": "https://github.com/microsoft/vscode/commit/3154a68fc151bcafe371f89d197412645e6a7616"
},
{
"finding_id": "CVE-2026-58650",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "GHSA-h6v9-3cqc-v234",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/06a2bc84d0555f4c7ebd176809673e61fa49c6ff"
},
{
"finding_id": "CVE-2026-47285",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "GHSA-vcpf-2mpp-vx3v",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-buffer-copy-extensions.diff",
"link": "https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61"
},
{
"finding_id": "CVE-2026-65675",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-3hjg-cwxj-qfc6",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-3hjg-cwxj-qfc6",
"note": "Copilot Chat security feature bypass - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-70335",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "GHSA-w79w-rj9h-vg4f",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-w79w-rj9h-vg4f",
"note": "Copilot Custom Agent Hook RCE - Copilot not present in Code Editor"
},
{
"finding_id": "CVE-2026-59113",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "GHSA-36qf-jgq9-4m6j",
"affected_versions": "< 1.132.1",
"patch_path": "N/A",
"link": "https://github.com/advisories/GHSA-36qf-jgq9-4m6j",
"note": "Fetch Web Page OS protocol handler RCE - webContentExtractor is electron-main only, not present in Code Editor web/reh-web builds"
},
{
"finding_id": "CVE-2026-69306",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
},
{
"finding_id": "GHSA-6xp2-9cj3-f488",
"affected_versions": "< 1.132.1",
"patch_path": "patches/common/fix-network-filter-domain-validation.diff",
"link": "https://github.com/microsoft/vscode/commit/af3a976e194030a94f6bfb5aebc5e0f4d66f5e41"
}
]
109 changes: 109 additions & 0 deletions patches/common/fix-block-privileged-url-payload.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
Block privileged URL payload options in server

Prevents environment variable injection via startParamsEnv by ensuring
VSCODE_* critical vars cannot be overridden, sanitizes resolverEnv before
use in terminal channel, removes dangerous env vars case-insensitively
across all platforms, and restricts extension dev payload options to
non-production builds only.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ef3ccf912287348aafd04dc6cc2c5619d6ccb70f
@finding-id: CVE-2026-70336 GHSA-fp6w-v29h-43rj CVE-2026-69320 GHSA-h29r-p8vr-4vfm
Index: b/src/vs/base/common/processes.ts
===================================================================
--- a/src/vs/base/common/processes.ts
+++ b/src/vs/base/common/processes.ts
@@ -3,7 +3,7 @@
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/

-import { IProcessEnvironment, isLinux } from './platform.js';
+import { IProcessEnvironment } from './platform.js';

/**
* Options to be passed to the external program or shell.
@@ -136,13 +136,16 @@ export function removeDangerousEnvVariab
return;
}

- // Unset `DEBUG`, as an invalid value might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/130072
- delete env['DEBUG'];
-
- if (isLinux) {
- // Unset `LD_PRELOAD`, as it might lead to process crashes
- // See https://github.com/microsoft/vscode/issues/134177
- delete env['LD_PRELOAD'];
+ const dangerousEnvVariables = new Set([
+ 'DEBUG',
+ 'NODE_OPTIONS',
+ 'VSCODE_NODE_OPTIONS',
+ 'LD_PRELOAD',
+ 'DYLD_INSERT_LIBRARIES'
+ ]);
+ for (const key of Object.keys(env)) {
+ if (dangerousEnvVariables.has(key.toUpperCase())) {
+ delete env[key];
+ }
}
}
Index: b/src/vs/server/node/extensionHostConnection.ts
===================================================================
--- a/src/vs/server/node/extensionHostConnection.ts
+++ b/src/vs/server/node/extensionHostConnection.ts
@@ -40,12 +40,10 @@ export async function buildUserEnvironme
const env: IProcessEnvironment = {
...processEnv,
...userShellEnv,
- ...{
- VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
- VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
- VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
- },
- ...startParamsEnv
+ ...startParamsEnv,
+ VSCODE_ESM_ENTRYPOINT: 'vs/workbench/api/node/extensionHostProcess',
+ VSCODE_HANDLES_UNCAUGHT_ERRORS: 'true',
+ VSCODE_NLS_CONFIG: JSON.stringify(nlsConfig)
};

const binFolder = environmentService.isBuilt ? join(environmentService.appRoot, 'bin') : join(environmentService.appRoot, 'resources', 'server', 'bin-dev');
Index: b/src/vs/server/node/remoteTerminalChannel.ts
===================================================================
--- a/src/vs/server/node/remoteTerminalChannel.ts
+++ b/src/vs/server/node/remoteTerminalChannel.ts
@@ -9,6 +9,7 @@ import { cloneAndChange } from '../../ba
import { Disposable } from '../../base/common/lifecycle.js';
import * as path from '../../base/common/path.js';
import * as platform from '../../base/common/platform.js';
+import { removeDangerousEnvVariables } from '../../base/common/processes.js';
import { URI } from '../../base/common/uri.js';
import { IURITransformer } from '../../base/common/uriIpc.js';
import { IServerChannel } from '../../base/parts/ipc/common/ipc.js';
@@ -210,7 +211,9 @@ export class RemoteTerminalChannel exten
};


- const baseEnv = await buildUserEnvironment(args.resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
+ const resolverEnv = { ...args.resolverEnv };
+ removeDangerousEnvVariables(resolverEnv);
+ const baseEnv = await buildUserEnvironment(resolverEnv, !!args.shellLaunchConfig.useShellEnvironment, platform.language, this._environmentService, this._logService, this._configurationService);
this._logService.trace('baseEnv', baseEnv);

const reviveWorkspaceFolder = (workspaceData: IWorkspaceFolderData): IWorkspaceFolder => {
Index: b/src/vs/workbench/services/environment/browser/environmentService.ts
===================================================================
--- a/src/vs/workbench/services/environment/browser/environmentService.ts
+++ b/src/vs/workbench/services/environment/browser/environmentService.ts
@@ -302,8 +302,8 @@ export class BrowserWorkbenchEnvironment
extensionDevelopmentKind: undefined
};

- // Fill in selected extra environmental properties
- if (this.payload) {
+ // Extension host development options from the payload are only valid in development builds.
+ if (this.payload && !this.isBuilt) {
for (const [key, value] of this.payload) {
switch (key) {
case 'extensionDevelopmentPath':
47 changes: 47 additions & 0 deletions patches/common/fix-buffer-copy-extensions.diff
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
Always return copies of buffers to extensions

Returns a copied slice of the buffer in extHostCommands instead of
the original backing ArrayBuffer, preventing extensions from mutating
shared memory. Also simplifies webview stream chunk handling to use
VSBuffer.buffer which already returns a safe Uint8Array copy.

Remove when Code-OSS is updated to >= 1.132.1.

@backported: https://github.com/microsoft/vscode/commit/ae7a28076f3076a10bd07b49cf7ff730c1773e61
@finding-id: CVE-2026-47285 GHSA-vcpf-2mpp-vx3v
Index: b/src/vs/workbench/api/common/extHostCommands.ts
===================================================================
--- a/src/vs/workbench/api/common/extHostCommands.ts
+++ b/src/vs/workbench/api/common/extHostCommands.ts
@@ -101,7 +101,8 @@ export class ExtHostCommands implements
return extHostTypeConverter.location.to(obj);
}
if (obj instanceof VSBuffer) {
- return obj.buffer.buffer;
+ // Create a copy of the buffer since the original buffer is owned by the extension host and might be reused for other commands
+ return obj.buffer.buffer.slice(obj.buffer.byteOffset, obj.buffer.byteOffset + obj.buffer.byteLength);
}
if (!Array.isArray(obj)) {
return obj;
Index: b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
===================================================================
--- a/src/vs/workbench/contrib/webview/browser/webviewElement.ts
+++ b/src/vs/workbench/contrib/webview/browser/webviewElement.ts
@@ -820,7 +820,7 @@ export class WebviewElement extends Disp
onData: (chunk) => {
if (!closed) {
try {
- controller.enqueue(new Uint8Array<ArrayBuffer>(chunk.buffer.buffer as ArrayBuffer, chunk.buffer.byteOffset, chunk.buffer.byteLength));
+ controller?.enqueue(new Uint8Array(chunk.buffer));
} catch {
closed = true;
this._activeStreamControllers.delete(controller);
@@ -861,7 +861,7 @@ export class WebviewElement extends Disp
});
listenStream(result.stream, {
onData: (chunk) => {
- const data = new Uint8Array(chunk.buffer.buffer, chunk.buffer.byteOffset, chunk.buffer.byteLength);
+ const data = new Uint8Array(chunk.buffer);
this._send('did-load-resource-chunk', { id, data }, [data.buffer]);
},
onError: () => {
Loading